Cyber attackers gained unauthorised access to two small privately operated water systems in Colorado in late August, changing settings on devices used to manage the facilities.
The attackers disabled remote access and alarms and modified pumping cycles. However, authorities said the intrusions did not affect drinking water quality, public safety or the continuity of water supplies.
What Did the Hackers Change?
The attackers gained access to certain connected devices at the two facilities and altered their settings for a period of time.
Changes included switching off remote access, disabling alarms and modifying the timing or sequence of pumping cycles.
Such systems are used to monitor and manage water operations, meaning unauthorised changes can potentially interfere with how a facility functions.
How Many People Were Affected?
Both facilities are relatively small, with each providing drinking water to fewer than 200 people.
Despite the operational changes, customers did not lose their water supply.
Authorities also reported no deterioration in drinking water quality following the incidents.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Was Water Treatment Affected?
Officials said the attackers did not disrupt the water treatment process at either facility.
The companies operating the systems detected the unusual activity and took steps to regain control of the affected equipment.
Operations were subsequently returned to normal, and the incidents were reported to authorities.
Who Was Behind the Attacks?
The identity and motive of the attackers remain unclear.
Authorities have not publicly established whether the two Colorado incidents were connected or formed part of a wider cyber campaign against water infrastructure.
The incidents occurred amid warnings from US authorities about attempts by Iran-backed cyber groups to access drinking water and wastewater infrastructure. However, officials have not confirmed any connection between those groups and the Colorado attacks.
Why Are Small Water Systems at Risk?
Smaller water utilities can face particular cybersecurity challenges because they may operate with fewer technical personnel and more limited cybersecurity resources than large municipal systems.
At the same time, water facilities increasingly depend on connected equipment and digital controls for monitoring and managing operations.
Remote access allows authorised personnel to operate or monitor equipment without being physically present, but compromised access can also provide attackers with a route into operational systems.
What Are Investigators Examining?
Investigators are examining how the attackers obtained access and which devices were compromised.
They are also trying to determine whether the same method was used against both facilities and whether the incidents have any connection to a broader campaign.
The two companies regained control after identifying the unauthorised activity, while the investigation into the intrusions continues.
The420 Takeaway: Critical Infrastructure Is a Cyber Target
The Colorado incidents show that cyberattacks on critical infrastructure do not have to target large facilities. Even small water systems can face attempts to manipulate operational equipment.
In these cases, water quality and supply remained unaffected, but the ability to alter alarms and pumping cycles highlights the importance of securing remote access and connected control systems.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics